Linux.MulDrop.14 is a Linux worm that searches for Raspberry Pi network systems whose default root password has not been changed, and after infiltrating them and obtaining ZMap and sshpass, it begins mining an unspecified cryptocurrency. In this way, the infected Raspberry Pi will become a source of revenue for the creator of this Linux worm.
Experts say that initial infection will occur when Raspberry Pi operators keep their devices’ SSH ports and external connections open.
After a Raspberry Pi-based device is affected by Linux Maldrop 14, the malware changes the default password for the “pi” user account to the following:
\$6\$U1Nu9qCp\$FhPuo8s5PsQlH6lwUdTwFcAUPNzmr0pWCdNJj.p6l4Mzi8S867YLmc7BspmEH95POvxPQ3PzP029yT1L3yi6K1